Tag: data
-
20 Flaws in Fertility Tracker Risked Data Loss, Fake Results
Mira Ultra 4 Fixes Vulnerabilities After University Team Hacked Bluetooth, Firmware. Multiple vulnerabilities identified in a popular at-home fertility tracking device could have allowed attackers to impersonate the device, manipulate hormone readings, access sensitive health information and reverse engineer production firmware, said the researchers who made the discovery. First seen on govinfosecurity.com Jump to article:…
-
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used…
-
ExfilSquad Targets New Victims, Shares Data via Torrents
Tags: dataFirst seen on resecurity.com Jump to article: www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents
-
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own…
-
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It…
-
Data Poisoning: Warum vergiftete Daten eine wachsende Gefahr für die IT-Sicherheit sind
Tags: dataFirst seen on t3n.de Jump to article: t3n.de/news/data-poisoning-warum-vergiftete-daten-eine-wachsende-gefahr-fuer-die-it-sicherheit-sind-1756214/
-
The Hidden Risks of Ignoring API Security During Mobile Application Security Testing
Mobile applications don’t operate in isolation. Behind every login screen, payment flow, and push notification sits a network of APIs quietly moving data between the app, the backend, and third-party services. Yet when organizations plan mobile application security testing, API security is often treated as an afterthought, something to “get to later” once the app’s……
-
Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients
Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered…
-
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Tags: access, authentication, business, cve, data, exploit, flaw, intelligence, software, sql, vulnerability, zero-dayMetabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain…
-
Forcepoint’s Ronan Murphy on securing the data layer AI just set on fire
First seen on scworld.com Jump to article: www.scworld.com/resource/forcepoints-ronan-murphy-on-securing-the-data-layer-ai-just-set-on-fire
-
Practice Management Firm Notifies 3.8M of 2025 Breach
Ohio-Based Unlimited Technology Systems Serves Thousands of Medical Practices. Practice management and financial software firm Unlimited Technology Systems is notifying 3.8 million people of an October 2025 data theft. The third-party vendor hack currently ranks as the largest health data breach reported to federal regulators so far in 2026. First seen on govinfosecurity.com Jump to…
-
ISMG Editors: AI Is Supercharging Attackers
Also: CIOs Rethink Data in AI Rollouts, ShinyHunters Hits Biotech. In this week’s panel, four ISMG editors discussed new research showing how AI is making cyberthreat actors more capable, why the technology is forcing CIOs to rethink data platforms they spent years modernizing and a string of attacks in the biotech sector. First seen on…
-
How AI Agents Widen the Enterprise Blast Radius
AWS’s Matt Girdharry and Varonis’ Matt Radolec on Data Security, Machine-Speed Risk. Agentic AI can act at machine speed across data, APIs and cloud services, expanding enterprise risk beyond traditional controls. AWS’ Matt Girdharry and Varonis’ Matt Radolec explain why AI governance, least privilege and runtime visibility now matter more than ever for security teams.…
-
Snowflake Hacker Pleads Guilty After Breaches Exposed Data of at Least 100 Million People
A hacker tied to the 2024 Snowflake customer breaches pleaded guilty after attacks exposed data tied to at least 100 million people. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-snowflake-hacker-guilty-data-breach/
-
Financial Services Under Fire From Rebranded Extortionists
What’s in a Name? Vishing-Savvy BlackFile Rebrands as Redact, Pink, Helix, Falcon. Data theft extortion group BlackFile claimed retire in May. Threat researchers at Google said telemetry and attack infrastructure shows that the group has carried on using a variety of new brand names and shifted its focus to targeting financial services. First seen on…
-
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
-
Unlimited Technology Systems breach impacts 3.8 million people
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/
-
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture.”…
-
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671.”UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
Computer maker Framework notifies ‘all customers’ of a data breach
Framework told “all” of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks
This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure. First seen on thecyberexpress.com Jump…
-
French rugby club Stade Français restores systems after cyberattack, probes data leak
The club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain fully operational. First seen on therecord.media Jump to article: therecord.media/french-rugby-club-restores-systems-after-cyberattack
-
NSFOCUS LAS: Comprehensive Log Management for Security Visibility and Compliance
The Log Management Challenge Most enterprises accumulate log sources the same way they accumulate infrastructure: one device at a time, each generating data in its own proprietary format. The result is logs scattered across security appliances, network devices, servers, databases, middleware, applications, and cloud workloads, with no unified view and unknown device status. Any issue……
-
Frontier AI Has a Cybersecurity Expertise Problem
First OpenAI’s model went rogue and broke out of testing containment to hack real systems, then Anthropic, and now Meta AI. Do you see a trend? Here is what it means: Although these frontier AI companies employ some of the world’s brightest engineers, architects, and developers, technical excellence is not the same as deep cybersecurity…

